G. BALAMURALIKRISHNA Mobile No. 09885663102 Email: krish_g@rediffmail.com JOB OBJECTIVE Seeking assignments in Information Security consulting with a technology-oriented organisation. SUMMARY OF EXPERIENCE & SKILLS 7 years’ experience in Systems/Security Administration with GENPACT, India and with Public sector Bank Oriental Bank of Commerce Have worked on numerous Security/System integration projects for Banking industry and Multinational clients like General Electric company (GE) and Oriental Bank of commerce Significant hands on experience in various Security Products Checkpoint Firewalls, Cisco PIX Firewall, Nortel Contivity VPN Router, RSA SecurID, ISS Site Protector, etc during tenures at GENPACT, India IT SKILL SET OS Network Security Products Sun Solaris, Novell 4.1, Novell Netware 4.1 SFT111, Windows 2000/03 Server, SCO Unix Open server Rel. 5.0, Checkpoint Firewall with Application Intelligence on Nokia IP380 Cisco PIX Firewall 525, 535 Nortel VPN Contivity 2700 RSA ACE Server / SecurID for Two Factor Authentication Internet Security Systems (ISS) – Site Protector Desktop Firewall – Desktop Proventia IT CERTIFICATIONS Checkpoint Certified Security Administrator (CCSA) Checkpoint Certified Security Expert (CCSE) ISS Certified expert (ISS-CE) RSA Certified Security Professional CAREER PROFILE 16th September 2004 with GENPACT, Hyderabad as Security Support Specialist in Security Operations Centre (SOC) Managing GENPACT, India Internet Gateway Security Infrastructure Team of 4 Security specialist managing Internet Gateway Infrastructure, Responsibilities include L3 support for Cisco PIX and Checkpoint Firewall and other Security Products, Firewalls: Scripting and Script review for Cisco PIX Firewall Implementing Firewall rules in PIX after obtaining necessary approvals as per organisation Security Policy Auditing Cisco PIX Firewall as per policy. Handling Critical change management and incident management for 45 nos. of Firewalls, Nortel Contivity, RSA ACE Server, Proxy, etc Managing 20 nos. Checkpoint Firewalls R55 on Nokia IPSO 3.8 cluster Administration of SideWinder Proxy G2 appliance for creating plug proxies to public network Process orientation, incident response, incident analysis for critical issues related to Network Security. VPN Implementing Site to site VPN tunnels for external sites Managing Virtual Private Network like establishing site to site and Remote Site VPN connectivity to external sites Dial VPN using Nortel Contivity 2700 Site to Site VPN from PIX to PIX Site to Site VPN from Cisco VPN concentrator to Cisco PIX Cisco PIX to Cisco PIX VPN using Crypto commands Administration of Nortel Contivity 2700 for Dial VPN infrastructure IDS Designing, Implementation and Administration of Site Protector SP5 for 1500 Desktop Proventia clients across GENPACT Implementation of Agent Manager, Event Collectors, Database and Application server Fine tuning Desktop Proventia policies regularly Ensuring all Agent Managers are updated with latest XPUs Two Factor Authentication Design, Implementation and Administration of Authentication in India, Hungary, Mexico and China RSA ACE Server for Two Factor Projects handled: 1. Implementation of RSA ACE Primary Server at Hyderabad and implementation of Replica servers at Gurgaon, China, Hungary and Mexico for two factor authentication 2. Implementing new security Infrastructure for GENPACT, Global Dial VPN at Hyderabad, Gurgaon, China, Hungary, Mexico Installation of Nortel Contivity 2700 VPN Router for Dial VPN at Hyderabad, Gurgaon, China, Hungary and Mexico. Configuring Nortel Contivity for Dial VPN Integrating RSA for Two Factor Authentication 3. Implementation of Site protector at GENPACT, India Site Protector SP5 implementation at Hyderabad, Gurgaon and Bangalore Installation of Site Protector Application, Database server, Agent Managers, Event Collectors. Creating Agent Build for Desktop Proventia and rolling out the agents for 1500 Laptops/Desktops using script. Centralised Management and Defining Policies 4. Implementation of Tacacs Authentication and Authorisation across all PIX Firewalls for RSA Hard Token two factor authentication 5. Upgrading of Checkpoint Firewall on Nokia IP380 The project involved upgrading of Checkpoint Firewall R54 to R55 Upgrading of Nokia IPSO 3.7 to IPSO 3.8 6. Implementation of SSL VPN (Client Less VPN for GENPACT) The Project involved implementation of Clientless VPN for GENPACT Since Aug’00 to September 2004 with Oriental Bank of Commerce, Secunderabad as Asst. Manager, Information Technology E- Security Department Responsibilities: (from 1St July 2002 to 1st September 2004) Designation: Assistant Manager (Information Security) 1. Implementation and Administration of Checkpoint Firewall Systems for Banks Corporate Network 2. Designing and implementing suitable Security Policies on Firewall systems based upon requirement 3. Implementation of Monitoring of Intrusion Detection Systems, updating latest signatures on IDS systems regularly 4. Scanning and detecting operating systems vulnerabilities for Windows 2000 and Solaris on various Servers in LAN. Regularly hardening of operating system. Updating patches regularly 5. Implementation and Administration of ACE Server for Two Factor Authentication for critical Servers. 6. Maintenance of Internet Banking Servers, Application and Database Servers. Ensuring 100% uptime 7. Administration Proxy Server, Websense for URL filtering, DNS Servers, etc 8. Maintenance of Leased line to VSNL for Internet Banking and Internet Browsing. 9. Administration of Interscan Messaging Suite (IMSS) for outgoing and Incoming mails. 10. Evaluation of Suitable Security Products for Security Infrastructure 11. Administration of Interscan Messaging Virus Wall (IMVV) and updating anti virus patches regularly 12. Process orientation, incident response, incident analysis for critical issues related to Network Security. Responsibilities: (from August 2000 to July 2002) Designation: Assistant Manager: Infrastructure Management Accessing of IT requirements for the Bank for Main Data Center at Secunderabad and for Internet Banking Center. Pilot site testing of new product / technologies Maintenance & support activities / Trouble shooting of problems on Servers across Bank. Implementing centralised Backup Management Solution and Centralised SAN Storage solution in co-ordination with all Project heads. Identifying suitable product / technology / optimum solution in specific cases Market watch of various products with latest technology for new Desktop PCs, Servers, Printers, etc. Technical Evaluation of products for various departments for Datacenters at Secunderabad, Mumbai and for Internet Banking Center Escalations of maintenance issues with vendors First level support for Operating system (UNIX) / Hardware related issues to users across branches. Major Contributions: Projects Handled during Tenure Setting up Security Infrastructure for Oriental Bank of Commerce, Secunderabad (Data Centre), which consists of Checkpoint Firewall implementation at Corporate, Perimeter and mail and proxy Zone. The project involves high availability and load balancing solution from Stonebeat for Checkpoint Firewall system. The Security Infrastructure comprises of Intrusion Detection Systems (Host based and Network based), Websense for URL filtering, IMSS (Interscan Messaging Suite) for content filtering SMTP traffic, Proxy Server for Internet Browsing and authentication. Implementation of Two Factor RSA Authentication scheme for critical Database and Application Servers. Successfully implemented Cisco 2610 Router with three Ethernet Interfaces bypassing the Corporate Firewall which can be put in place of Corporate Firewall in case of any maintenance activities are carried out at Internet banking Center. Implementation of Enterprise Solution SAN at Main Datacentre, OBC, Secunderabad and Disaster Recovery Centre, Mumbai at OBC : Environment: Compaq Alpha Servers configured in cluster environment, EMA 12000 Centralised Storage with 1.5 TB HD, Cloning with Raid 1 + 0 configuration, TL895 Tape Library (Backup), Unix OS, Tru Cluster and 8-port SAN switches Designing, Planning of Centralised Backup management for Windows platform at OBC Description: The project involved the technical comparison of Tape Library Solution from various vendors like HP, IBM, etc Backup software Veritas, HP Openview, IBM Tivoli at the Main Data Centre & Disaster Recovery Centre, and implementation of Centralised Backup Management Solution from HP. The project also involved getting approval from management after reporting the necessary comparisons. Implementation of Centralised Backup Solution for Core Banking with Legato Networker Backup Software OBC, Datacentre at Secunderabad. Integration of Legato Backup Software with TL895 Tape Library for backup. Aug’98-Aug’00 with J. P. Computer Services Pvt Ltd., Vasco-da-Gama, Goa as Customer Support Engineer (Authorised WIPRO Service Franchisee and Value Added Dealer) Projects Handled during Tenure Handled several system integration projects on multi-environment platforms, viz., Windows, SCO Unix, Sun Solaris and Novell NetWare, for clients including: Setting up new Systems Infrastructure for the following customers which includes Installation of Servers, Installation of Novell Netware SFTIII, Windows Operating system, Configuring clients, etc Mormugao Port Trust, Vasco-da-Gama Goa University, Panaji (Goa) Corporation Bank, Panaji Global Trust Bank, Panaji Bharti Duraline, Verna Citizen Co-operative Bank Ltd., Vasco-da-Gama Margaum Urban Co-operative Bank, Goa (5 branches) Projects handled 1. Customs, Goa The Project involves installation and implementation of two numbers SUN Enterprise 1 Server with Solaris 2.6 Operating system configured in Cluster environment with Jeeva for high availability software and Open Disk Suite for Mirroring for RAID 0, 1. Installation of 25 PCs with all client software to be run 2. Salgaocars, Vasco-da-Gama The project involves installation of SUN E450 SUN Server with Solaris 2.6 Operating System. Disk Mirroring with RAID. Installation of Oracle 7 Database on Solaris Platform. Setting up of network and configuring clients. Setting up of 30 clients. Jan’97-Aug’98 with J. P. Computer Services Pvt. Limited, Hubli as Customer Support Engineer (Authorised Service Franchisee of WIPRO Infotech Ltd.) Projects Handled during Tenure Worked on multi-platform (Windows, Sun Solaris, SCO Unix and Novell NetWare) projects for major clients like: Setting up new Systems Infrastructure for the following customers which includes Installation of Servers, Installation of Novell Netware SFTIII, Windows Operating system, Configuring clients, etc North Canara G.S. Bank, Karwar (Network set up) Corporation Bank, Hubli/Bank of India, Hubli Sundaram Motors, Hosur, Hubli LIC and HFL, Dharwad ACADEMIC QUALIFICATIONS Diploma in Electrical & Electronics Engineering from the Board of Technical Examinations, Bangalore in 1995. TRAINING PROGRAMMES ATTENDED RSA Two Factor Authentication training. RSA ACE server and Replica servers. Administration of RSA ACE server. Types of RSA tokens (software/Hardware). RADIUS and TACACS communication. Synchronising RSA server with Active Directory, etc from RSA Security, Singapore – March 2005 Training on Cisco PIX Firewall, Administration of Cisco PIX Firewall and Cisco VPN Concentrator – November 2004 Trained in Internet Security Systems (ISS) products like Implementation of Site Protector, Desktop Proventia, Agent Managers, Event Collectors, etc from ISS, Singapore – December 2004 Certified Ethical Hacking (CEH) training. Various Security threats and how to overcome the threats. Various hacking tools available. Protection against threats. – November 2004 Training on Checkpoint/Cisco PIX Firewall Installation and Administration, Authentication schemes (TACACS, RADIUS, RSA Secure ID) Applet Trapper, ActiveX Filtering, Content Security, Load Balancing Intrusion Detection System (IDS), Virtual Private Network (VPN) – December 2000 Training on Sun products and Sun Solaris 2.6, 2.7, 2.8 conducted by Wipro Infotech Ltd., Bangalore which includes installation and Administration of Solaris Operating System, Disk Suite configuration for mirroring, Network File System (NFS), etc – August 1999 Training on Cisco Routers (configuration of Cisco routers, Routing Tables, Classes of IP address, subnet masking and different models of Cisco Routers) conducted by Wipro Infotech Ltd., Bangalore – December 1997 Reference: Mr. GVS RAMAMURTHY Team Lead Microsoft India Ltd. Phone No. 9849046536 DATE OF BIRTH: 30th June 1976 CONTACT ADDRESS: Flat No. G-202, Bhavya’s Anandam, Nizampet Road, Kukatpally, Hyderabad Residence Ph-040-23898710